Licensing

"We Used the Open Source Version"

It is the most common reply we see to a dual-licence infringement claim in Asia-Pacific. Read carefully, it is not a defence. It is an admission — and it usually leaves the company in a worse position than the claim it was meant to answer.

A vendor sends a notice. Twelve seats of a commercial component, no licence on record. The reply arrives three weeks later, usually from counsel, usually in one sentence: we used the open source version.

Vendors tend to treat that answer as the end of the road. It sounds technically informed, it is difficult to disprove from outside the company, and pursuing it looks expensive. A great many Asia-Pacific files are closed at exactly this point.

They should not be. In our experience the open source reply is one of the weakest positions a company can take, because of what it concedes.

Why the product exists in two versions at all

Dual licensing is not a trap. It is a deliberate business model, and a common one. The vendor publishes the same code twice: once under a copyleft licence such as GPL v3, and once under a commercial licence.

The copyleft edition is free of charge but not free of conditions. If you distribute software built on it, you must pass on the corresponding source under the same terms. For a company that sells closed-source products, that is usually unacceptable — which is precisely why the commercial edition exists. You are not paying for different code. You are paying to be released from the disclosure obligation.

Understood that way, the two editions are not alternatives. They are two prices for the same thing, and the currency of the free one is your source code.

What the defence actually concedes

Consider what has just been admitted. The company confirms it obtained the software, installed it, and used it in its work. Infringement is no longer in dispute. What is now asserted is that a licence covered that use.

So the question becomes narrow and answerable: was the licence complied with?

Under GPL v3, distributing a binary obliges you to make the corresponding source available under the same licence. If the company shipped a product containing that code and did not publish the source, it did not meet the condition. And a copyleft licence is conditional — fail the condition and the grant terminates automatically (GPL v3, §8). The company is then in the position of having used the software with no licence at all.

The cure provision, stated accurately

GPL v3 §8 allows reinstatement. A first-time violator who cures within 30 days of notice from the copyright holder is automatically reinstated. This matters and should be acknowledged — but curing means actually publishing the corresponding source of everything already shipped. Companies that reach for the open source defence are almost never willing to do that. The provision that could save them is the one they refuse to use.

That is what we mean when we say the defence closes itself. It cannot be maintained without either releasing source code the company considers proprietary, or conceding that a commercial licence was required.

Where the defence genuinely holds

It is worth being precise here, because a vendor who overstates this loses credibility in the first exchange with opposing counsel.

Copyleft obligations attach to distribution, not to use. A company that runs a GPL build entirely inside its own walls, ships nothing, and gives nothing to a separate legal entity has no source disclosure obligation. That is by design, and it is the correct reading of the licence.

How the software is usedCopyleft obligations
Internal use only, nothing shippedNot triggered
Embedded in a product delivered to customersTriggered — corresponding source required
Shipped in a device or applianceTriggered, with installation information for user products
Provided to a contractor or affiliate as a separate entityGenerally triggered
Operated as a hosted serviceNot triggered by GPL — triggered by AGPL §13

So the honest position is this: the open source defence is real, and it is available to a company that has genuinely kept the software inside. The problem is that most companies reaching for it have not.

The verification problem, and who owns it

Here is the objection every vendor raises next. If the company claims internal use only, how would anyone ever prove otherwise? You cannot see inside their network.

That framing puts the burden in the wrong place. Infringement has already been conceded. What is being asserted now is a licence — and a party asserting a licence carries the obligation to show that its conditions were met. The correct response to the open source reply is not an investigation. It is a request: then demonstrate it.

Demonstrating it is unpleasant. It means opening release history, customer delivery records, build artefacts, and transfers to affiliates and contractors. Companies that were telling the truth can do this in an afternoon. In our experience, most of the ones that reach for this defence would rather settle than start.

What the outside of the building still shows

Meanwhile, a claim of purely internal use leaves more traces outside the company than people expect. We are not describing intrusive investigation here — this is material that is public, purchasable, or already in the vendor's own systems.

The one that closes files most often is the simplest. We read the company's own website and note what it sells: product names, module names, the branding on its solution pages. Then we look at the evidence already in hand and find those same names appearing as project directories, build paths, and component identifiers. A company that has just told you the software never left the building has, in its own artefacts, tied it to the product it sells to customers.

Other material sits in plain view:

  • Shipped artefacts — installers, firmware, mobile applications, container images, published packages. If it is sold, it can be obtained and examined.
  • Third-party notices in customer documentation. Present, and distribution is conceded. Absent, and a separate notice obligation has been missed.
  • Version strings exposed by customer-facing systems.
  • Tender and procurement filings, which frequently itemise components.
  • Recruitment postings, engineering blogs and conference talks, in which companies describe their own architecture in detail.
  • Software bills of materials supplied to their own customers or regulators.
  • The vendor's own records — download logs, update requests, trial registrations, licence server contacts, carrying corporate domains and addresses.

The last two deserve emphasis. SBOM disclosure requirements have spread quickly, and a company that declared the component to its customer has created a record it does not control. Neither does it control the vendor's server logs.

What this means for a vendor holding a closed file

If you shelved an Asia-Pacific matter because the reply cited open source, the file is very likely still live. Three questions decide it.

  1. Does the company sell a product that could plausibly contain the component? If yes, internal-use-only is a claim that has to survive contact with its own catalogue.
  2. Has it published corresponding source for anything it ships? If not, the copyleft route was never open to it.
  3. Is there any prior commercial relationship — a trial, an old licence, an evaluation? Those agreements frequently carry audit provisions, and that is the cleanest path to resolution available.

In short

  • The open source reply concedes use. It moves the dispute from whether the software was used to whether a licence was complied with.
  • Copyleft is conditional. No corresponding source for distributed builds means no licence, which is a worse position than the original claim.
  • Internal use only is a legitimate defence — for companies that can show it.
  • The obligation to show it belongs to the party asserting the licence, not to you.
  • Product names on a company's own website have a way of reappearing in its build paths.

This article reflects patterns MIRAE WEB has encountered in licence enforcement work across Asia-Pacific since 2012. No client, matter or settlement is identified. It is general commentary, not legal advice; licence obligations and enforcement procedure differ by jurisdiction, and specific matters should be assessed with local counsel.

Was your file closed with "we used the open source version"?

Send it to us. Those are the matters we reopen.

Show us the case →